Patrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThiefQuest | ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable. |
| T1041 Exfiltration Over C2 Channel |
MalwareThiefQuest | ThiefQuest exfiltrates targeted file extensions in the |
| T1071.001 Web Protocols |
MalwareThiefQuest | ThiefQuest uploads files via unencrypted HTTP. |
| T1105 Ingress Tool Transfer |
MalwareThiefQuest | ThiefQuest can download and execute payloads in-memory or from disk. |
| T1106 Native API |
MalwareThiefQuest | ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration. |
| T1486 Data Encrypted for Impact |
MalwareThiefQuest | ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information. |
| T1554 Compromise Host Software Binary |
MalwareThiefQuest | ThiefQuest searches through the |
| T1620 Reflective Code Loading |
MalwareThiefQuest | ThiefQuest uses various API functions such as |
| T1622 Debugger Evasion |
MalwareThiefQuest | ThiefQuest uses a function named |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.